MEDIUM 5.5 PyPI
CVE-2026-8643
PYSEC-2026-196 · CVE-2026-8643
Published · Modified
Description
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.
Ready to move
Start Securing
Free, no credit card | First findings in minutes